peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,829 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2001-0818 EXP A buffer overflow the '\s' console command in MDBMS 0.99b9 and earlier allows remote attackers to execute arbitrary commands by sending the command a… Patch early 7.5 high 4% 2001-12-06
CVE-2009-1443 EXP Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors. Patch early 10.0 high 4% 2009-04-27
CVE-2018-19459 EXP Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file. Patch early 7.8 high 4% 2018-11-22
CVE-2013-7179 EXP The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute arbitrary commands via shell met… Patch early 8.3 high 4% 2014-02-04
CVE-2007-1423 EXP Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code vi… Patch early 9.3 high 4% 2007-03-13
CVE-2023-30868 EXP Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions. Patch early 7.1 high 4% 2023-05-18
CVE-2005-1503 EXP Multiple SQL injection vulnerabilities in MidiCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) searchstring… Patch early 7.5 high 4% 2005-05-11
CVE-2006-4993 EXP Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 4% 2006-09-26
CVE-2007-1225 EXP The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in a URL, which might allow remot… Patch early 10.0 high 4% 2007-03-02
CVE-2007-3251 EXP Multiple directory traversal vulnerabilities in e-Vision CMS 2.02 and earlier allow remote attackers to (1) include and execute arbitrary local files… Patch early 7.8 high 4% 2007-06-18
CVE-2006-1747 EXP PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root p… Patch early 7.5 high 4% 2006-04-12
CVE-2006-0688 EXP PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 4% 2006-02-15
CVE-2007-6188 EXP Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute arbitrary local files via a ..… Patch early 7.5 high 4% 2007-11-30
CVE-2015-6098 EXP Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and… Patch early 7.2 high 4% 2015-11-11
CVE-2018-8410 EXP An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevat… Patch early 7.8 high 4% 2018-09-13
CVE-2003-1405 EXP DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3. Patch early 7.5 high 4% 2003-12-31
CVE-2005-4065 EXP SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitrary SQL commands via unknown v… Patch early 7.5 high 4% 2005-12-07
CVE-2007-3935 EXP PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code v… Patch early 9.3 high 4% 2007-07-21
CVE-2005-2210 EXP Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL. Patch early 7.5 high 4% 2005-07-11
CVE-2005-2644 EXP Buffer overflow in JaguarEditControl.dll in Isemarket JaguarControl allows remote attackers to cause a denial of service (crash) and possibly execute… Patch early 7.5 high 4% 2005-08-23
CVE-2006-5014 EXP Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladm… Patch early 8.8 high 4% 2006-09-27
CVE-2007-0585 EXP include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conff… Patch early 9.3 high 4% 2007-01-30
CVE-2007-2506 EXP WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service… Patch early 7.8 high 4% 2007-05-04
CVE-2017-5633 EXP Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) chang… Patch early 8.0 high 4% 2017-03-06
CVE-2007-4220 EXP Directory traversal vulnerability in Motorola Timbuktu Pro before 8.6.5 for Windows allows remote attackers to create or delete arbitrary files via a… Patch early 7.8 high 4% 2007-08-29
CVE-2009-3753 EXP Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension… Patch early 7.5 high 4% 2009-10-22
CVE-2006-4060 EXP PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 4% 2006-08-10
CVE-2007-2495 EXP Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers to cause a denial of service (… Patch early 7.5 high 4% 2007-05-04
CVE-2006-5895 EXP PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary PHP code via a URL in the roo… Patch early 7.5 high 4% 2006-11-14
CVE-2007-1590 EXP The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device cra… Patch early 7.8 high 4% 2007-03-21
← previous page 210 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt